What's your
HackRisk Score?
We scan your external attack surface and deliver a board-ready report with your risks and remediation advice, free of charge, within 24 hours.
Up and running in minutes.
No complex setup. No professional services engagement. Just your domain - and full visibility into your cyber risk posture.
Vigilance for cyber security risks, before they cost you.
HackRisk is a cyber risk monitoring platform for UK businesses that have no dedicated security team. It watches your organisation from the outside, the way an attacker would, across six areas: dark web exposure, external reconnaissance, vulnerabilities, phishing resilience, security awareness training and supply chain risk. Everything it finds rolls into one HackRisk Score, a percentage graded A* to F, so you can see where you stand before reading a technical report. Scanning is continuous and agentless, which means nothing to install and nothing to schedule. Findings come with advice on how to fix them rather than only a list of what is wrong. Your first report is free, lands within 24 hours and includes 30 days of platform access with no card details. HackRisk is built by CyberLab, whose accreditations include CREST and ISO 27001.
From free report to continuous monitoring.
- Step 1
Request your free report
No card details needed.
- Step 2
We map your external attack surface
Recon scanning maps everything your organisation exposes externally.
- Step 3
Six domains scanned
Dark web, recon, vulnerability, phishing simulation, awareness training and supply chain.
- Step 4
You get a HackRisk Score
A single grade, A*–F, summarising your cybersecurity posture.
- Step 5
Your report within 24 hours
It includes 30 days of access to the HackRisk portal.
- Step 6
Continuous monitoring
Monitoring runs continuously across all six domains.
Actionable, board-ready, on demand.
Our automated threat reports break down the HackRisk findings to provide actionable recommendations that can be communicated across your organisation.
Four security tools, one score.
Think like a hacker. Map every asset.
We uncover all your online assets - even those you might not know about - providing a complete picture of your attack surface.
- Discover websites, SSL certificates, IP addresses, APIs, and cloud services
- Continuously assess external-facing systems
- Proactively address security risks and reduce exposure
Findings will land where your team already works.
We’re building integrations so alerts reach Slack or Microsoft Teams and raise tickets in the tools you already run, turning a new risk into a job someone owns. These are on the roadmap rather than live today.
Questions worth asking.
What is HackRisk?
HackRisk is a platform developed to be your early warning system for cyber security risks. An affordable, lightweight solution to keep your environment secure between rounds of penetration testing. This unique bundle gives you continuous, outside-in visibility across your entire attack surface - identifying weaknesses, discovering hidden assets, and understanding how much of your information is already in the hands of bad actors.
What is my HackRisk Score?
In your HackRisk Report, you'll see a risk level for each of the constituent services, and an overall risk score to show your current threat level. Your overall score accounts for the highest level of risk identified overall, and how vulnerable that would leave your systems to a threat actor. Use it to track your progress as you reduce risks across your environment.
How does HackRisk keep my business safe?
By continuously assessing your exposure to security risks, HackRisk gives you all the information you need to proactively address security risks and reduce your exposure to cyber threats. Expert resolution advice within the platform helps you to resolve vulnerabilities and data breaches, and provides best practice to avoid incidents.
Do I have to install anything?
Nothing to get started. Your free HackRisk Report and all external scanning run from the outside and are read-only, so there is no software to roll out and your production systems are never touched. The exception is the internal vulnerability scan included with HackRisk Core, which covers 5 endpoints and does need something installed on the systems you want scanned from the inside.
What risks does HackRisk identify?
HackRisk identifies exposed assets, open ports, breached credentials, emerging vulnerabilities, and other potential entry points in real time. Exposed web assets - including admin panels, subdomains, login pages, expired certificates, open databases, and APIs - are mapped to help you visualise your attack surface.








